Malicious PDF — malware analysis report

Static analysis result for SHA-256 f076a8fca562fa9b…

MALICIOUS

PDF

40.5 KB Created: 2020-08-29 14:07:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b0ef790fff67be7b8da7746d9bf745c SHA-1: d3439129c8296b27b813cee504c54c9ca2c407a1 SHA-256: f076a8fca562fa9bf63b88322e680eaab965378a2b08453a811e433fdfaaef24
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, a technique often used in link farms to manipulate search engine results or to host a large number of redirectors. One of the primary links points to 'ttraff.com', which is flagged as a malicious redirector. The document body, though heavily obfuscated, contains the same URL, reinforcing its malicious intent. The presence of numerous links to external PDFs suggests an attempt to obscure the final malicious destination.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=chhattisgarh+khadya+suraksha+adhiniyam+2012+pdf
    • https://static.usrfiles.com/ugd/b8c837_fb0b068f3bd44d729797f132ed3b1342.pdf
    • https://static.usrfiles.com/ugd/b8c837_b089d3b1d70b428681402cc08f38a9eb.pdf
    • https://static.usrfiles.com/ugd/b8c837_afd93b34cf5044dc8fdf7ef74441fcd7.pdf
    • https://cdn.shopify.com/s/files/1/0435/4136/4890/files/zojilulonutoni.pdf
    • https://cdn.shopify.com/s/files/1/0463/0282/2557/files/dotikefejebakipekuzeget.pdf
    • https://cdn.shopify.com/s/files/1/0437/5412/7521/files/path_of_war.pdf
    • https://static.usrfiles.com/ugd/b8c837_a49fb5a83d01440d879dfc837c48a278.pdf
    • https://static.usrfiles.com/ugd/b8c837_16b7fe9c1eda4e3a8115e9b9889cfa88.pdf
    • https://static.usrfiles.com/ugd/b8c837_9d68b757b6564f6597666d79b09c24aa.pdf
    • https://static.usrfiles.com/ugd/b8c837_efec9eb68e56477fb6a6a8eed6735244.pdf
    • https://static.usrfiles.com/ugd/b8c837_323fc7260c8e4fbf8ba06a48e7f2aac7.pdf
    • https://cdn.shopify.com/s/files/1/0428/2885/7503/files/raxamuvonobedosu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/lujodegiduwidixerilaji.pdf
    • https://cdn.shopify.com/s/files/1/0435/5116/2523/files/ver_soul_plane_espaol.pdf
    • https://cdn.shopify.com/s/files/1/0430/3893/3146/files/kutolegaxubutes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005550.bin
60f37c199b2c50cf4b79750d5959de5fd2c782caa6f738e02a7f8d22a3ad1569
pdf-font-stream PDF embedded font (sfnt) at offset 0x5550 5820 bytes
font_01_sfnt_off000068f5.bin
78e94e2e47178245ca437e301e19f50dc99845ecc02da2ba30fe2b1e34051cc2
pdf-font-stream PDF embedded font (sfnt) at offset 0x68F5 2092 bytes
font_02_sfnt_off0000729a.bin
d64e0f5ae6036b70b6049ee39315365a63dd88fa648bf3d19de30cd78eabae1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x729A 10176 bytes